Threat Advisory

Ivanti Neurons ITSM Remote Code Execution Flaws Let Attackers Execute Arbitrary Commands

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Ivanti Neurons for ITSM versions 2025.2, 2025.3, 2025.4, and 2026.1.

Unauthenticated Deserialization (CVE-2026-12744, CVE-2026-12745)
Two critical flaws – both CWE-502 Deserialization of Untrusted Data, CVSS 9.8 – let a remote attacker with no credentials at all execute arbitrary code on the server. The attacker simply sends a malicious serialized payload over the network. No login, no privileges, and no user interaction are required.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Ivanti Neurons for ITSM versions 2025.2, 2025.3, 2025.4, and 2026.1.

Unauthenticated Deserialization (CVE-2026-12744, CVE-2026-12745)
Two critical flaws – both CWE-502 Deserialization of Untrusted Data, CVSS 9.8 – let a remote attacker with no credentials at all execute arbitrary code on the server. The attacker simply sends a malicious serialized payload over the network. No login, no privileges, and no user interaction are required.[emaillocker id="1283"]

Authenticated RCE Flaws (CVE-2026-12650, CVE-2026-12648, CVE-2026-12651)
Three additional deserialization bugs affect authenticated attackers. CVE-2026-12650 scores 9.9 (Critical) because its scope is changed – a compromise can spill beyond the vulnerable component. CVE-2026-12648 and CVE-2026-12651 both score 8.8 (High). All three require only low-level privileges.

Missing Authorization Flaws (CVE-2026-12645, CVE-2026-12646, CVE-2026-12647)
Three CWE-862 Missing Authorization vulnerabilities each score 9.9 (Critical). A low-privileged authenticated user can trigger protected server-side functionality without proper checks. This again results in arbitrary code execution on the server.

Ivanti has confirmed no exploitation in the wild at the time of disclosure.

RECOMMENDATION:

We recommend you to update Ivanti Neurons for ITSM to version 2026.2.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu